Agent Lead ExchangeAgent Lead Exchange
Home
Security overview

The controls we run — described honestly.

This page is maintained by the Agent Lead Exchange team to answer common security and privacy questions. It describes controls we actually operate today; it is not an independent certification or a substitute for our Privacy Policy and Terms.

Authentication & session controls

Password + email sign-in with optional TOTP multi-factor authentication and one-time backup codes.

Sensitive actions (payout changes, admin operations) require a fresh step-up verification.

Login alerts email you when a session starts from a new device or location.

Data access scoping

Every table enforces database-level access rules — you only see the leads, referrals, and payouts your account owns.

Admin-only tables (roles, audit log) reject client reads unless you hold the corresponding role.

Client contact info is hidden on public and unclaimed-teaser surfaces (city-level pins only).

Money movement

The broker or title company pays each party directly from the closing disbursement packet. Agent Lead Exchange never holds agent funds.

The platform's disclosed share is paid at settlement — never in advance and never on canceled deals.

See How payouts work for the full lifecycle.

ReferralProof™ audit trail

Every closed referral is reconciled against MLS records, uploaded proof, and platform activity.

Discrepancies open a cure case with an automated notice to both agents and the receiving broker.

Brokers can request a signed audit packet at any time.

Data handling

Data is stored in a managed Postgres database with encryption in transit and at rest.

Backups run continuously; we retain the last 30 days of point-in-time recovery.

You can export or delete your account data from Settings → Account.

Access & administration

Platform staff access is restricted to super-admin roles required for support and dispute review.

All admin actions write to an immutable audit log tied to the user ID and timestamp.

Third-party integrations (Google Maps, Facebook Lead Ads, and platform billing) are read/write-scoped to the minimum needed.

Report a vulnerability

If you believe you have found a security issue, email security@agentleadexchange.com with steps to reproduce. We acknowledge reports within 3 business days and will keep you posted through resolution.

Please do not perform testing that could disrupt service for other users, exfiltrate customer contact info, or violate privacy law. Coordinated disclosure only.

For a walkthrough of the payout split and dispute mechanics, see Trust & Transparency.